package com.lanou3g.code0523.permission;

import javax.servlet.*;
import javax.servlet.annotation.WebFilter;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpSession;
import java.io.IOException;
@WebFilter (filterName = "AdminFilter",urlPatterns = "/admin/*")
public class AdminFilter implements Filter {
    @Override
    public void init(FilterConfig filterConfig) throws ServletException {

    }

    @Override
    public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
                    //判断是否是管理员登录
        HttpServletRequest request= (HttpServletRequest) servletRequest;
        HttpServletResponse response = (HttpServletResponse) servletResponse;
        HttpSession session =request.getSession();
        User user = (User) session.getAttribute("user");
        if (user!=null&&user.isAdmin()){
            //是管理员登录
            filterChain.doFilter(request,response);
        }else {
            //不是管理员或没有登录
          response.sendRedirect("/login.html");
        }
    }

    @Override
    public void destroy() {

    }
}
